A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers.
Which option will protect the individual servers?
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers.
Which option will protect the individual servers?
To protect individual DNS servers from denial-of-service (DoS) attacks and prevent resource exhaustion, applying a classified DoS Protection Profile is the most appropriate measure. This profile allows for the specialized protection of specific critical resources such as DNS servers, which are common attack targets. Other options like enabling packet buffer protection on the Zone Protection Profile or using DNS sinkholing are broader measures that do not target individual server protection as precisely as a classified DoS Protection Profile.
Correct is D They want to protect just one specific server, if you apply the zone protection you are protecting the entire zone
The explanation we all need. Thanks!
Answer:D
:D smiling face
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/dos-protection-profiles-and-policy-rules/classified-versus-aggregate-dos-protection#id56c14277-0ecd-4e32-b3d3-7b616176204a D.
D. Single protection is for DoS.
D is the right answer Packet Buffer protection is indeed the way to protect against resource exhaustion, but it is not configured under DoS protection profile. It is directly enabled under Zones.
Correct is D DOS protection if for resources behind the firewall. Zone Protection is for the firewall.
D is correct.
for one specific server
D is correct
Answer D is the correct one. Classified profiles protect individual critical resources, especially servers that users access from the internet, and are often attack targets, such as web servers, database servers, and DNS servers. Please refer to https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/dos-protection-profiles-and-policy-rules/classified-versus-aggregate-dos-protection
Correct answer : D
Correct answer is D
D. Apply a classified DoS Protection Profile.
D is the correct answer
Definitely D is correct
D -- it couldn't be else
D is the correct answer, for specific servers not the entire zone so correct answer is not A